Impact
A flaw in the ByteCoreStack – MCP Connector for AI Tools plugin allows an authenticated user with a Subscriber role or higher to overwrite WordPress user capabilities on their own account. The vulnerability lies in the MCP tool that uses WordPress’s wp_update_user_meta function but only checks for the ability to edit a user, which resolves to a read capability when the target ID matches the caller’s ID. Because the meta key blocklist in this plugin does not protect the wp_capabilities and wp_user_level keys, an attacker can set the wp_capabilities meta key to include an administrator role. On the next request, WordPress loads the user as an administrator, granting full site control. The weakness is a classic example of Privilege Escalation (CWE‑269).
Affected Systems
All versions of the ByteCoreStack – MCP Connector for AI Tools plugin for WordPress up to and including 1.2.3 are affected. No specific operating system or WordPress core version is mentioned, but the vulnerability exists in the plugin code itself and therefore applies to any WordPress installation using these plugin versions.
Risk and Exploitability
The flaw carries a high CVSS score of 8.8, indicating significant severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the existence of a user‑authenticating endpoint means that exploitation can occur remotely over the MCP JSON‑RPC interface. Because the attacker only needs to be logged in with a Subscriber‑level account or higher, the risk of exploitation is high in environments where such accounts exist without strict role management.
OpenCVE Enrichment